跳至主要内容

Compliance and Third-Party Notices

This page lists key third-party software that llm.port deploys, integrates, or depends on.

Each third-party component remains licensed by its original authors under its own terms.

提示

For compliance and reproducibility, pin Docker images to exact versions and/or digests rather than floating tags.

Core stack (container images)

ComponentExample image(s)Typical license
PostgreSQLpostgres:*PostgreSQL License
pgvectorpgvector/pgvector:*PostgreSQL License
Redisredis:*BSD-3-Clause / newer dual-licensed variants
RabbitMQrabbitmq:*MPL 2.0
MinIOminio:* / hardened variantsAGPLv3 + commercial options

Observability stack

ComponentExample image(s)Typical license
Grafanagrafana/grafana:*AGPLv3
Lokigrafana/loki:*AGPLv3
Alloygrafana/alloy:*Apache 2.0
OTel Collectorotel/opentelemetry-collector-contrib:*Apache 2.0
Jaegerjaegertracing/all-in-one:*Apache 2.0

Langfuse

  • Typical images: langfuse/langfuse:*, langfuse/langfuse-worker:*
  • Core licensing: MIT for OSS core (enterprise terms can differ)

Document processing (optional)

  • Typical image: ds4sd/docling-serve:*
  • Typical license: MIT
  • Note: model licenses used alongside document tooling may have additional terms

Python dependency highlights

AreaExample packages
API and servicesFastAPI, SQLAlchemy, Alembic, httpx
Privacy/NLPpresidio-analyzer, presidio-anonymizer, spaCy
Observabilityopentelemetry-sdk, prometheus-client, sentry-sdk
CLIClick, Rich, Textual

Frontend dependency highlights

AreaExample packages
UI frameworkReact, React DOM
UI toolkitMUI, Emotion
Routing and stateReact Router
Table/interactionTanStack Table, dnd-kit
StylingTailwind CSS

Public compliance commitments

  • Maintain attribution and third-party notice accuracy
  • Track dependency and license posture as part of release governance
  • Keep internal SBOM and legal review workflows current
  • Generate and retain SBOM per release
  • Pin image versions and maintain changelogs for upgrades
  • Review license posture in security/compliance checkpoints
备注

This page provides a practical public summary. Internal compliance operations should retain the full component-level and version-level license inventory.

本文档由 AI 辅助生成,可能存在不准确之处。请在生产使用前核验关键细节。